VYPR
Unrated severityNVD Advisory· Published Jan 17, 2024· Updated Jun 2, 2025

Inadequate access control in C21 Live Encoder and Live Mosaic

CVE-2024-0642

Description

Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to access the application as an administrator user through the application endpoint, due to lack of proper credential management.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Inadequate access control in C21 Live Encoder and Live Mosaic 5.3 allows remote attackers to gain administrator access without credentials.

Vulnerability

Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3, allows a remote attacker to access the application as an administrator user through the application endpoint, due to lack of proper credential management [1]. The affected versions are C21 Live Encoder and Live Mosaic 5.3.

Exploitation

An attacker with network access to the application endpoint can exploit this vulnerability without any authentication. No special privileges or user interaction are required. By directly accessing the endpoint, the attacker gains administrator-level access [1].

Impact

Successful exploitation grants the attacker full administrative privileges, leading to complete compromise of confidentiality, integrity, and availability of the affected system. The CVSS v3.1 base score is 9.8, with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [1].

Mitigation

The vulnerabilities have been resolved by the Cires21 team in the latest software version of the affected products, which was released in the last week of November 2023 [1]. Users should update to the latest version to mitigate this vulnerability. No workarounds are provided in the advisory.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.